DoesNotBelong Changelog
=====================

v9.3.2 (10.05.2025)
- Database update

v9.3.1 (10.05.2025)
  • Improved Stage 1 - Process killing. Any console errors should now be gone. Tested on Windows 10 and 11 x64
  • On newer systems without WMIC.exe, powershell.exe is now able to terminate suspicious processes impersonating legitimate files even if they include encoded UTF8 - UTF16 filepaths. This should alleviate all previous 'binary file matches' found in logs
  • Fixed a bug that would occur during Packages scan. Wrong file read

v9.3.0 (10.04.2025)
  • Improved Stage 1 - Process killing
  • Added a link for reporting bugs via Github to the log header
  • Added Donation Link line to footer of log. Donating helps me stay enthusiastic and motivated to continue finding improvements to the program
  • Removed detection for font cache for now. It may return later

v9.2.9 (10.03.2025)
-Updated resource icon

v9.2.8 (10.01.2025)
-Updated database: BitCoinMiner. figmaUpdater

v9.2.7 (09.29.2025)
-Updated database: Rugmi & BitCoinMiner
-Bug fix: Database related

v9.2.6 (09.29.2025)
-Updated database

File can be found here: https://furtivex.net/docs/DNB_Changelog.txt
  • Like
Реакции: Sandor
  1. Database updates
  2. Task whitelist updated
  • Like
Реакции: akok
  • Added translations: Scottish Gaelic & Filipino
  • Added automatic cleanup for MountPoints2 registry keys.
  • Added a network repair routine for a particular case of ReasonLabs DNS install
  • Added Packages (AppXPackages) automatic clean up
  • Added automatic cleanup and repair of Authentication Packages registry value (often used by ScreenConnect)
Код:
HKLM\System\CurrentControlSet\Control\Lsa\\Authentication Packages value was missing -> restored
HKLM\System\CurrentControlSet\Control\Lsa\\Authentication Packages value contained extras -> restored
  • Like
Реакции: Guest и akok
In the case of particular miner (TROJ.BTCMiner.GoogleUP) which breaks Windows Update functionality, the tool now stops the relevant services and a few others related to Windows Update before patching the registry for a greater chance of success. Afterwards, the services are restarted. This hopefully eliminates the need for the user to patch the registry in Safe Mode, where those services are already in a stopped state.
  • Like
Реакции: Guest и akok
  • Updated task whitelist: Microsoft Intune related tasks
  • Database update
  • Like
Реакции: Guest
  • Database update
  • Added telemetry services from HP.
  • The tool no longer creates a restore point. It is recommended to create your own Restore Point or volume snapshot before running the tool if you are concerned about losing something important.
  • Like
Реакции: Guest
  • Finished adding personalized threat names to give the user a better idea of what type of infection they have. Example:
Код:
C:\Users\owner\AppData\Roaming\Microsoft\MicrosoftWeb.{7007BCC7-3202-11D1-AAD2-00E05FC1270E} (TROJ.BTCMiner.GoogleUP)
I couldn't do this everywhere due how the tool functions, but they are added where possible.
  • Fixed an issue where some folders were not being deleted
  • Process whitelist updated to include Emsisoft AV
  • HKLM...\Winlogon [Shell] and [Userinit] values checked and repairs made
  • Clearing the event viewer logs is now logged and some other logging has been revised. Example:
Код:
# Miscellaneous:

[?] AntiVirus Software: Windows Defender
[?] Event Viewer Logs were cleared
[?] Restore Point: Does Not Belong PRESCAN - Created
  • Database updated
  • Like
Реакции: Guest
-Database update
- Optimizations done by removing a couple of redundant searches
  • Like
Реакции: Guest
v7.8.2+ includes a check to ensure the user is running the latest version. Fetches the update if it's available.
  • Like
Реакции: Guest
Old name: Furtivex Malware Removal Script
Newer name: DoesNotBelong
  • Like
Реакции: Vvvyg и Guest
Назад
Сверху Снизу